← volver
CVE-2025-62349

Salt Master authentication protocol downgrade may enable minion impersonation

CVSS 7.5 HIGHEPSS 0.4%CWE-287
Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and circumventing protections introduced in response to prior issues.
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Productos afectados
Salt Project · Salt

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →